CVE-2026-67100
- EPSS 0.35%
- Veröffentlicht 18.09.2026 07:53:02
- Zuletzt bearbeitet 08.10.2026 20:37:08
HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate ...
CVE-2026-67101
- EPSS 0.27%
- Veröffentlicht 18.09.2026 07:50:10
- Zuletzt bearbeitet 08.10.2026 20:36:46
HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible fr...
CVE-2025-31985
- EPSS 0.16%
- Veröffentlicht 20.05.2026 11:28:03
- Zuletzt bearbeitet 24.07.2026 10:10:00
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpre...
CVE-2025-31973
- EPSS 0.18%
- Veröffentlicht 20.05.2026 11:25:44
- Zuletzt bearbeitet 24.07.2026 10:10:00
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the applicati...
CVE-2024-30151
- EPSS 0.25%
- Veröffentlicht 06.05.2026 18:14:11
- Zuletzt bearbeitet 07.05.2026 17:06:09
HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthorized users to gain elevated privileges, bypassing intended access restrictions. This may result in expo...
CVE-2025-31960
- EPSS 0.24%
- Veröffentlicht 06.05.2026 18:02:52
- Zuletzt bearbeitet 07.10.2026 09:10:00
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-vie...
CVE-2025-31974
- EPSS 0.18%
- Veröffentlicht 06.05.2026 18:01:39
- Zuletzt bearbeitet 07.10.2026 09:10:00
HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow unintended modifications to critical system components, potentially increasing the risk of system c...
CVE-2025-31975
- EPSS 0.17%
- Veröffentlicht 06.05.2026 13:51:40
- Zuletzt bearbeitet 07.10.2026 09:10:00
HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal software versions and system details, potentially aiding attackers in targeting known vulnerabilities.
CVE-2025-52613
- EPSS 0.23%
- Veröffentlicht 06.05.2026 13:50:47
- Zuletzt bearbeitet 07.10.2026 09:10:00
HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation a...
CVE-2025-31976
- EPSS 0.16%
- Veröffentlicht 06.05.2026 13:49:39
- Zuletzt bearbeitet 07.10.2026 09:10:00
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrated. .